Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
U.S.-China Economic and Security Review Commission

U.S.-China Economic and Security Review Commission Vendor Cyber Rating & Cyber Score

uscc.gov

The U.S.-China Economic and Security Review Commission (USCC) was created by the United States Congress on October 30, 2000 by the Floyd D. Spence National Defense Authorization Act for 2001 (codified at 22 U.S.C. §7002) with the legislative mandate to monitor, investigate, and submit to Congress an annual report on the national security implications of the bilateral trade and economic relationship between the United States and the People’s Republic of China, and to provide recommendations, where appropriate, to Congress for legislative and administrative action. In accordance with its mandate, the Commission focuses its work and study on the following eleven areas: proliferation practices, economic transfers, energy and natural


UESRC A.I CyberSecurity Scoring

UESRC
Company Information
Website:https://uscc.gov/
Employees number:64
Number of followers:8,629
NAICS:
Industry Type:Government Relations
Homepage:uscc.gov
UESRC Risk Score (AI oriented)
Between 600 and 649
logo
UESRCGovernment Relations
Updated:
12/05/2026
616/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
UESRC Global Score (TPRM)
xxxx
logo
UESRCGovernment Relations
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

UESRC
UESRCPoor
Current Score
616Caa (POOR)
01000
4 incidents
-38.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
624Before Incident
JUNE 2026
621Before Incident
MAY 2026
674Before Incident
Cyber Attack
11 May 2026UESRC
Google and U.S. telecommunications providers: Opinion | I Ran the N.S.A. This Is How to Defeat China’s Hacker Army.

China’s Cyber Espionage Campaigns Target U.S. Critical Infrastructure and Intellectual Property

616After Incident
CRITICAL-58
U.SGOO1778560014
China’s Cyber Espionage Campaigns Target U.S. Critical Infrastructure and Intellectual Property A growing cyber threat from China has exposed vulnerabilities in America’s critical infrastructure and corporate networks, prompting calls for a stronger, coordinated defense strategy. State-sponsored hacking groups, including Volt Typhoon and Salt Typhoon, have infiltrated hundreds of U.S. utility systems and telecommunications providers, positioning malware to disrupt water and electrical supplies while intercepting communications from senior officials and millions of Americans. Beyond sabotage, China-backed actors continue to steal $225 billion to $600 billion in U.S. intellectual property annually, according to a 2017 report by the Commission on the Theft of American Intellectual Property. The scale of these operations underscores the limitations of the current voluntary information-sharing model between private companies and the government, which has proven insufficient in countering persistent threats. A potential solution emerged in February 2026, when Google disrupted a Chinese espionage campaign targeting 53 organizations across 42 nations. By cutting off attackers’ cloud storage access, revoking network permissions, and neutralizing their command-and-control tools, Google demonstrated how private-sector intervention could achieve in days what years of government advisories could not. This incident highlights the need for a shared responsibility framework, where tech and cybersecurity firms proactively identify and neutralize threats similar to how the banking industry combats fraud. However, legal ambiguities have deterred some companies from taking decisive action. To address this, policymakers are considering updates to cybersecurity laws, including explicit authorization for private-sector disruption operations against foreign state actors. Proposals also include establishing a specialized court, modeled after the Foreign Intelligence Surveillance Court (FISC), to oversee and approve such operations a recommendation from the Center for Strategic and International Studies (CSIS). These changes aim to empower companies to act without fear of legal repercussions while maintaining accountability.
INCIDENT DETAILS -
TYPE
cyber espionageintellectual property theft
MOTIVATION
sabotageintellectual property theftespionage
IMPACT
Financial Loss: $225 billion to $600 billion annuallyData Compromised: communications from senior officials and millions of Americansutility systemstelecommunications providersOperational Impact: potential disruption of water and electrical supplies
DATA BREACH
Type Of Data Compromised: communications dataSensitivity Of Data: high (senior officials and millions of Americans)
APRIL 2026
691Before Incident
Cyber Attack
01 Apr 2026UESRC
U.S. companies: US accuses China of 'industrial-scale' campaigns to steal AI secrets ahead of Trump's Beijing trip

U.S. Accuses China of Large-Scale AI Espionage Ahead of Trump’s Beijing Visit

672After Incident
CRITICAL-19
U.S1777034696
U.S. Accuses China of Large-Scale AI Espionage Ahead of Trump’s Beijing Visit The U.S. has accused China of conducting "industrial-scale" cyber campaigns to steal American artificial intelligence (AI) secrets, escalating tensions just weeks before former President Donald Trump’s planned visit to Beijing. The allegations highlight a growing "AI arms race," with U.S. officials warning that the nation controlling AI advancements could dominate future technological and economic landscapes. According to reports, China is leveraging its vast intelligence apparatus to target U.S. companies, aiming to acquire sensitive AI research and proprietary data. The accusations come amid broader geopolitical friction, including trade disputes and military posturing in regions like the Strait of Hormuz, where U.S. forces have intercepted Iranian-linked vessels transporting sanctioned oil. The timing of the allegations just ahead of high-level diplomatic engagements underscores the strategic stakes of AI development, with implications for national security, economic competitiveness, and global influence. No specific details on the scope or methods of the alleged espionage have been disclosed.
INCIDENT DETAILS -
TYPE
Espionage
MOTIVATION
Technological and economic dominance, AI advancements
IMPACT
Data Compromised: Sensitive AI research and proprietary data
DATA BREACH
Type Of Data Compromised: AI research, proprietary dataSensitivity Of Data: High
MARCH 2026
691Before Incident
FEBRUARY 2026
690Before Incident
JANUARY 2026
689Before Incident
DECEMBER 2025
687Before Incident
NOVEMBER 2025
686Before Incident
OCTOBER 2025
684Before Incident
SEPTEMBER 2025
683Before Incident
AUGUST 2025
681Before Incident
JULY 2025
697Before Incident
Cyber Attack
01 Jul 2025UESRC
U.S. universities: Italy extradites alleged Chinese state hacker to US

Chinese National Extradited to U.S. Over Alleged State-Backed Cyberattacks on COVID-19 Research

678After Incident
CRITICAL-19
U.S1777308160
Chinese National Extradited to U.S. Over Alleged State-Backed Cyberattacks on COVID-19 Research A Chinese national, Xu Zewei, was extradited from Milan to the U.S. on Saturday after Italian authorities arrested him in July 2025. Xu faces charges of wire fraud, aggravated identity theft, and unauthorized access to protected computers, linked to his alleged role in a Chinese state-backed hacking group. U.S. officials accuse Xu of participating in cyber intrusions between February 2020 and June 2021, including the widespread HAFNIUM (Silk Typhoon) attacks that compromised thousands of systems globally. The group, allegedly directed by China’s Ministry of State Security (MSS) and Shanghai State Security Bureau (SSSB), targeted U.S. universities, immunologists, and virologists working on COVID-19 vaccine research. Court documents claim Xu breached a Texas university’s network and reported findings to SSSB supervisors. The HAFNIUM campaign, which exploited vulnerabilities in Microsoft Exchange Servers, affected over 60,000 U.S. entities, with more than 12,700 successfully compromised, according to the FBI. Xu’s alleged co-conspirator, Zhang Yu, remains at large. Xu, who denies involvement, was detained while vacationing in Milan with his wife. His extradition drew criticism from China’s Foreign Ministry. If convicted on all charges, he faces up to 77 years in prison. The case underscores ongoing tensions over state-sponsored cyber espionage targeting critical research and infrastructure.
INCIDENT DETAILS -
TYPE
Cyber EspionageState-Sponsored Attack
MOTIVATION
Theft of COVID-19 vaccine researchIntellectual property theftState-sponsored espionage
IMPACT
Data Compromised: COVID-19 vaccine research data, intellectual propertySystems Affected: Over 60,000 U.S. entities, with 12,700 successfully compromisedOperational Impact: Unauthorized access to protected computers and networksIdentity Theft Risk: Aggravated identity theft
DATA BREACH
COVID-19 vaccine researchIntellectual propertySensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes (aggravated identity theft charges)
MAY 2025
754Before Incident
Breach
01 May 2025UESRC
Telecommunications Providers and U.S. Government Surveillance System: FBI labels suspected China hack of law enforcement data 'a major cyber incident'

Chinese Cyber Intrusion into U.S. Government Surveillance System

695After Incident
CRITICAL-59
CHIU.S1775183062
FBI Declares Chinese Cyber Intrusion a "Major Incident" Amid National Security Concerns The FBI has classified a suspected Chinese cyber intrusion into a U.S. government surveillance system as a "major incident," citing risks to national security. According to senior law enforcement officials and sources familiar with the matter, the breach compromised sensitive law enforcement data, prompting the FBI to brief lawmakers on the incident. The intrusion is believed to employ tactics similar to those used by Salt Typhoon, a China-linked hacking group uncovered in 2024. That campaign, one of the largest intelligence compromises in U.S. history, breached major telecommunications providers, stealing phone records of millions of Americans and FBI wiretap data. Under the 1994 Communications Assistance for Law Enforcement Act (CALEA), telecoms must maintain surveillance systems for court-ordered wiretaps systems that Salt Typhoon accessed in 2024. China has denied involvement in the operation. Former officials describe the latest breach as part of a broader pattern of undeterred Chinese cyber operations, despite high-profile exposures like Salt Typhoon and diplomatic efforts to ease tensions. A former senior cybersecurity official noted that adversaries perceive U.S. defenses as weakened, particularly amid federal workforce reductions. Sen. Mark Warner (D-Va.), vice chair of the Senate Intelligence Committee, warned that the incident reflects a persistent threat from China and other cyber adversaries, who continue to exploit vulnerabilities in U.S. systems. He criticized recent cutbacks in cybersecurity staffing at agencies like the FBI and CISA, arguing that such reductions undermine national defenses at a critical time. Former FBI cyber official Cynthia Kaiser confirmed that China has long targeted U.S. communications to track intelligence and law enforcement activities. The latest intrusion was discovered after her departure from the agency in May. The FBI and CISA have not commented on the matter. The incident was first reported by Politico.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Intelligence gathering, tracking U.S. law enforcement and intelligence activities
IMPACT
Data Compromised: Sensitive law enforcement data, FBI wiretap data, phone records of millions of AmericansSystems Affected: U.S. government surveillance system, telecommunications providers' surveillance systems (under CALEA)Operational Impact: Compromised national security, undermined law enforcement surveillance capabilitiesBrand Reputation Impact: Undermined trust in U.S. cybersecurity defenses
DATA BREACH
Type Of Data Compromised: Law enforcement data, wiretap data, phone recordsNumber Of Records Exposed: Millions of Americans' phone recordsSensitivity Of Data: High (national security, intelligence, law enforcement operations)Personally Identifiable Information: Phone records

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for UESRC ?
?
What was UESRC's A.I Rankiteo Cyber Score in June 2026 ?
?
What was UESRC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was UESRC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was UESRC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was UESRC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was UESRC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was UESRC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was UESRC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was UESRC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was UESRC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was UESRC's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on UESRC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with UESRC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view UESRC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?